GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
70 advisories
Filter by severity
undici vulnerable to caching and replay of unsafe HTTP method responses
Low
CVE-2026-85008
was published
for
undici
(npm)
Sep 29, 2026
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
High
CVE-2026-102677
was published
for
electron
(npm)
Sep 29, 2026
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
High
CVE-2026-86039
was published
for
@libp2p/peer-store
(npm)
Sep 17, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
Moderate
CVE-2026-55663
was published
for
mediasoup
(npm)
Aug 25, 2026
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
High
CVE-2026-53728
was published
for
@medplum/core
(npm)
Aug 17, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
High
CVE-2026-68945
was published
for
@angular/common
(npm)
Aug 3, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
High
GHSA-pvcr-8mvp-w8qr
was published
for
@budibase/server
(npm)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
Moderate
CVE-2026-54288
was published
for
hono
(npm)
Jun 16, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Critical
CVE-2026-53513
was published
for
@better-auth/sso
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Critical
CVE-2026-53512
was published
for
better-auth
(npm)
Jul 7, 2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
High
CVE-2026-53516
was published
for
better-auth
(npm)
Jul 7, 2026
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
High
CVE-2026-54266
was published
for
@angular/common
(npm)
Jun 15, 2026
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
High
GHSA-77q5-rr5v-x43q
was published
for
openclaw
(npm)
Jul 2, 2026
sigstore-js has Insufficient Verification of Data Authenticity
Moderate
CVE-2026-48816
was published
for
@sigstore/verify
(npm)
Jul 1, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Unsafe default behavior breaks integrity check
Moderate
CVE-2026-50573
was published
for
pnpm
(npm)
Jun 26, 2026
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
Critical
CVE-2026-48063
was published
for
@whiskeysockets/baileys
(npm)
Jun 10, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
High
CVE-2026-45337
was published
for
better-auth
(npm)
Jun 4, 2026
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
Critical
CVE-2026-45058
was published
for
electerm
(npm)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API